← signals
2026-07-26·LANGFLOW·security risk
meddown

A cluster of security advisories has been published for Langflow, an open-source AI workflow tool, indicating serious...

A cluster of security advisories has been published for Langflow, an open-source AI workflow tool, indicating serious vulnerabilities including remote code execution, missing authentication, and path traversal.

window 30devidence 16confidence score 100

confidence score

Strong evidence: 3 independent source classes support this read.

100
medium confidence3 independent source classesofficialotherpasses publish gate

signal brief

A cluster of security advisories has been published for Langflow, an open-source AI workflow tool, indicating serious vulnerabilities including remote code execution, missing authentication, and path traversal. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-0770 to its Known Exploited Vulnerabilities catalog on July 21, 2026, requiring federal agencies to apply mitigations by July 24 (see CISA KEV entry). The Open Source Vulnerabilities (OSV) database has published 12 distinct advisories for Langflow between June 29 and July 13, 2026 (see PYSEC-2026-1521, PYSEC-2026-1522, PYSEC-2026-1523, PYSEC-2026-1524, PYSEC-2026-1525, PYSEC-2026-2565, PYSEC-2026-2566, PYSEC-2026-2567, PYSEC-2026-2568, PYSEC-2026-2569, PYSEC-2026-376, PYSEC-2026-377, PYSEC-2026-378, PYSEC-2026-379). These include critical issues such as remote code execution via validate_code(), missing authentication on critical API endpoints, and path traversal in knowledge bases. A dev release (1.12.0.dev6) was published on PyPI on July 26 (see PyPI), but no official patch has been confirmed for all listed CVEs. The accumulation of vulnerabilities suggests systemic security weaknesses, likely eroding developer trust and enterprise adoption.

What the sources said:

  • CISA: "Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code." (source)
  • OSV advisory PYSEC-2026-1524: "Langflow Missing Authentication on Critical API Endpoints." (source)
  • OSV advisory PYSEC-2026-379: "Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint." (source)

source data used

Decision support, not stock advice. This signal is research with cited evidence — not a recommendation to buy, sell, or hold any security.